CVE-2017-0883Incorrect Permission Assignment in Server

Severity
6.4MEDIUMNVD
EPSS
0.1%
top 75.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 5
Latest updateMay 13

Description

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NExploitability: 3.1 | Impact: 2.7

Affected Packages2 packages

CVEListV5nextcloud/nextcloud_serverAll versions before 9.0.55 and 10.0.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g265-v379-5vwj: Nextcloud Server before 92022-05-13
CVEList
CVE-2017-0883: Nextcloud Server before 92017-04-05
CVE-2017-0883 — Incorrect Permission Assignment | cvebase